LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Fullington Trailways Listed by dragonforce Ransomware Group

HIGH severityUnverified claimHow we verify

Fullington Trailways Listed by dragonforce Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 15, 2024
Fullington Trailways Listed by dragonforce Ransomware Group

Reported April 15, 2024.

HIGH
Severity
April 15, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Fullington Trailways Listed by dragonforce Ransomware Group (reported April 15, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who have used Fullington Trailways services, or who work with the company, face a practical concern: a ransomware group has publicly claimed to have taken internal files from the organization. When a transportation provider appears on a leak site, the immediate question for customers, employees, and partners is whether personal or operational information has left the company’s control and what that could mean for them in daily life.

Public reporting on 15 April 2024 noted that Fullington Trailways had been listed by the dragonforce ransomware group. The number of people affected remains unknown, and the precise contents of the material are described only as internal files taken in a ransomware attack. That limited picture still carries real weight for anyone whose details may sit inside those files.

What happened

According to the available record, Fullington Trailways was listed by the dragonforce ransomware group on or around 15 April 2024. The listing asserts that internal files were exfiltrated during a ransomware attack. No public figure has been given for the volume of data, the number of individuals involved, or the exact date the intrusion began. The method of initial access has not been disclosed. The claim rests on the group’s own leak-site posting; independent confirmation of the full scope has not been supplied in the facts at hand.

In short, the incident is framed as a ransomware event that included data theft, yet the operational details—how long the attackers remained inside the network, which systems were reached, and whether any ransom demand was paid—remain undisclosed.

Inside dragonforce

Dragonforce is a ransomware operation that has become known for double-extortion tactics: encrypting systems while also copying data and threatening to publish it if payment is not made. Like other groups in this category, it maintains a public leak site where it posts victim names and, at times, samples of stolen material to increase pressure. The group typically operates as a ransomware-as-a-service model, recruiting affiliates who carry out the intrusion and share proceeds with the core operators.

Public reporting on dragonforce has described campaigns against a range of sectors, often focusing on mid-sized organizations whose disruption can create operational urgency. The group’s listings are claims; they do not by themselves prove every detail of an intrusion. In this case, the facts state only that Fullington Trailways appeared on the group’s site with an assertion that internal files had been taken. No further statements attributed specifically to dragonforce about this victim—beyond the listing itself—are part of the record provided here.

About Fullington Trailways

Fullington Trailways, operating as Fullington Auto Bus Co. Inc., is a long-established transportation company based in Clearfield, Pennsylvania. Founded in 1908, it provides intercity scheduled bus services linking central Pennsylvania with destinations such as Pittsburgh, Harrisburg, and Wilkes-Barre, as well as Buffalo, New York. The company also offers charter and round-trip transportation, limousine services, VIP cruises, school-bus contracting, and related products such as gift cards. Since September 2009 it has operated as a subsidiary of RATP Développement.

Organizations of this type routinely handle passenger booking information, employee records, contractor details, route and scheduling data, and financial or operational documents needed to run a multi-state bus network. A breach involving internal files therefore touches both the people who ride the buses and the people who keep the service running. Because transportation companies sit at the intersection of public mobility and private data, any unauthorized removal of internal material raises questions about continuity of service and the protection of those records.

The information in question

The facts state that internal files were exfiltrated in a ransomware attack. No further breakdown of data types—such as names, contact details, payment information, or employee identifiers—has been disclosed. The number of people affected is listed as unknown.

Companies that operate scheduled and charter bus services typically maintain customer reservation data, employee personnel files, vendor contracts, and operational documents. Whether any of those categories were among the files claimed by dragonforce is unconfirmed. Readers should treat the exact contents as unverified until the organization or an official notification provides clearer detail.

Why it matters

For individuals, the practical risk is that personal or contact information, if present in the taken files, could be used for phishing, social-engineering calls, or identity-related fraud. Even limited internal documents can give attackers enough context to craft convincing messages that appear to come from the company or its partners. For employees and contractors, exposure of workplace records can create longer-term privacy and security concerns.

For the organization, the incident raises operational and reputational questions. Ransomware events often disrupt scheduling systems, customer communications, and internal coordination. Restoring systems and investigating the scope of data loss requires time and resources. Because Fullington Trailways serves both regular passengers and school-related contracts, any interruption or loss of confidence can affect a wide circle of users. The absence of confirmed numbers does not remove the need for caution; it simply means the full picture is still incomplete.

Were you affected?

If you have booked travel with Fullington Trailways, worked for the company, or done business with it, treat the listing as a signal to take basic protective steps while waiting for any official notice. Public detail remains limited, so these measures are precautionary rather than a confirmation that your data was involved.

Official updates from Fullington Trailways or its parent company remain the most reliable source of confirmation. Until those appear, the steps above offer a practical way to reduce risk without assuming the worst.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyFullington Trailways security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Fullington Trailways’s full breach history →

More recent breaches

Williams Tank Lines Listed by dragonforce Ransomware GroupDecember 14, 2024Oahu Transit Services Listed by dragonforce Ransomware GroupJune 16, 2024Ward Transport & Logistics Listed by dragonforce Ransomware GroupMarch 3, 2024President Container Group Listed by dragonforce Ransomware GroupMay 27, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Fullington Trailways Listed by dragonforce Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by dragonforce — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram